Junglewise Threat Intelligence

CVE-2020-2883: Oracle WebLogic Server Unspecified Vulnerability

CVE-2020-2883 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-01-07

Technologies: Oracle WebLogic Server. Vendors: Oracle.

Executive brief

An unspecified vulnerability in the Core component of Oracle WebLogic Server allows unauthenticated attackers with network access via the IIOP or T3 protocols to compromise the server. Successful exploitation can lead to a complete takeover of the affected Oracle WebLogic Server instance.

Affected products

  • Oracle WebLogic Server 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0

Timeline

  • 2020-04-14: advisory: Initial Oracle Critical Patch Update (CPU) advisory published.
  • 2025-01-07: kev added: Added to CISA's Known Exploited Vulnerabilities (KEV) catalog.
  • 2025-01-07: disclosed: Vulnerability published on NVD.

Related threats